Slack-native requests
Users run /request-access and approvers decide right in Slack. No new portal, no context-switch, no email chain.
BigBrotherBot turns every access request into a risk-scored, policy-checked, fully-audited decision — without anyone leaving Slack. Runs on your infrastructure. Licensed per seat.
One bot covers the whole lifecycle — from the request in Slack to the audit row your auditor reads a year later.
Users run /request-access and approvers decide right in Slack. No new portal, no context-switch, no email chain.
Every request is scored on sensitivity, first-time privilege, and more. Low risk auto-approves; high risk steps up to extra reviewers.
Define toxic combinations once. BBB flags conflicting grants before they're approved — not in next quarter's audit.
Grants are time-boxed by default. Access checks out for the window it's needed and expires on its own — no standing privilege left behind.
Approvers don't have to accept a request as-is. Change the role or shorten the expiry at decision time, then approve in one step.
Sync real access across your integrations — GitHub, GitLab, Google Workspace, Metabase, Vanta, Wizer and many more. Mismatches land in a triage queue for one-click remediation.
Hire and termination events drive boarding checklists automatically, with SCIM 2.0 inbound provisioning from your IdP. One authoritative source deactivates users — the rest just observe.
An RRULE rotation engine resolves who's on-call now and syncs Slack usergroups to match. Escalation policies, PTO auto-cover and handoff reports come built in — no separate paging tool.
Periodic access reviews, training campaigns and certification evidence — kept and retained so audits become a query, not a fire drill.
A full ticketing desk in Slack: SLA tiers, CSAT surveys, a knowledge base for deflection and round-robin assignment across your team.
Probe your services on a schedule — HTTP, TLS and journey checks feed a public status page and fire alerts the moment an SLO slips.
Wire up policies in a visual flow builder, or manage them as code. Export your config, review the plan, and apply it — GitOps for access.
From request to provisioned-and-audited — most of it without a human in the loop.
Someone runs /request-access, picks a service and gives a reason. That's the whole user experience.
BBB scores the risk, checks separation-of-duties, and routes to the right approvers — or auto-approves when policy allows.
The decision is recorded, the requester is notified, and the grant is tracked against what your integrations actually show.
Not every request needs a human. BBB scores each one and lets the routine ones through, so approvers only see what's actually risky.
BBB syncs what your integrations actually show and compares it to what was approved. When the two diverge, you hear about it.
BigBrotherBot is not a SaaS. You run it inside your own environment, so the most sensitive thing it touches — who can access what — never leaves your control.
Ships as a single Go service plus PostgreSQL. Deploy it on your Kubernetes, your VPC, your rules.
Every Slack webhook is signature-verified. Trusted-proxy handling keeps client IPs honest behind your load balancer.
Five roles and scoped permissions gate every admin action. Auth via Google OAuth or local password (bcrypt, cost 12).
Grants, denials, revokes, deletes and config changes are all recorded with retention controls for compliance evidence.
Integrations use narrowly-scoped credentials and per-source lifecycle authority — only one source may deactivate a user.
Per-user rate limiting, request-body limits and CSRF protection on the admin surface — sane defaults, configurable.
Community is free forever — up to 10 seats, with compliance and separation-of-duties checks free for everyone. Team and Enterprise add integrations, provisioning and more, licensed per seat.
Compliance & SoD checks are free for everyone, forever. Self-hosted, air-gap friendly, no phone-home.
See pricingThe things teams ask before they deploy.
Self-hosted. It ships as a single Go service plus PostgreSQL and runs entirely inside your own infrastructure — the access data it processes never leaves your environment.
Per active seat. Community is free forever up to 10 seats; Team and Enterprise are licensed per active seat and billed annually. Licenses are offline signed keys — air-gap friendly, no phone-home.
No. The free trial runs for 30 days with every feature and unlimited seats, and requires no credit card.
Drivers for GitHub, GitLab, Google Workspace, Slack, Jira, Metabase, Sentry, Cloudflare, Vanta, Wizer and more sync real access to detect drift. See the integrations page for the full list.
Most teams deploy in an afternoon — one container plus PostgreSQL on your Kubernetes or VPC. The quickstart walks through it.
Book a 20-minute walkthrough. We'll show you a real request flow, from Slack command to audit row.